Missing Authentication for Critical Function in Umbraco CMS - #VU153367
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to obtain content identifiers and editorial activity information.
The vulnerability exists due to missing authentication in back-office SignalR hubs when accepting client connections. A remote attacker can connect to the exposed endpoints and receive real-time notifications to obtain content identifiers and editorial activity information.
The activity information includes when content is created or edited, including unpublished content. Content itself, credentials and management capabilities are not exposed, and the issue does not allow content to be changed.